If [EMAIL PROTECTED] is banned from a Google Group and
[EMAIL PROTECTED] is registered with that group,
[EMAIL PROTECTED] can subscribe to a mailing list such as
Full-Disclosure and start forwarding all messages [EMAIL PROTECTED]
sends to that mailing list if [EMAIL PROTECTED] is registered to
it, and directly post them to the Google Group [EMAIL PROTECTED] is
banned from.

This is probably done by the banned [EMAIL PROTECTED] setting up a
filter on Gmail Settings > Filter > Matches:
from:([EMAIL PROTECTED])
Do this: Forward to ([EMAIL PROTECTED]).

Severity of this issue is obviously critical and you should switch the
victim's registered ([EMAIL PROTECTED]) e-mail address on a Google
Group to "moderate" as a work around, until Google Groups fixes this
vulnerability.

Google Inc. (GOOG) was notified simultaneously as this security
advisory was published to the wild.

http://finance.google.com/finance?q=NASDAQ:GOOG/

http://groups.google.com/

http://google.com/

All the best,

n3td3v

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Reply via email to